At a Glance
- Tasks: Lead and shape the company's information security strategy in a hybrid cloud environment.
- Company: Heywood creates innovative software solutions for businesses, transforming financial journeys with Agile methodologies.
- Benefits: Enjoy a hybrid working model, e-learning subscriptions, and fun social events like bake-offs and game nights.
- Why this job: Join a dynamic team where your voice matters and contribute to a culture of innovation and learning.
- Qualifications: Expertise in information security, cloud security principles, and relevant industry certifications are essential.
- Other info: We value diversity and encourage applicants from all backgrounds to apply.
The predicted salary is between 43200 - 72000 £ per year.
Do you thrive on shaping information security goals and setting the direction and vision of information security, specifically in a hybrid cloud environment? Does identifying potential security vulnerabilities across multiple platforms and planning remediation activities come as second nature to you? Do you have the technical security expertise to ‘shift left’ when it comes to increasing the maturity of information security operations as part of cloud development? Do you have hands-on experience managing information, cybersecurity incidents, and data breaches? If so, then you could be just what we are looking for. Read on to find out more…
As Head of Information Security at Heywood, your role will be to develop, shape and update the Company’s information security capability, ensuring our hybrid cloud environment remains secure against an ever-changing threat landscape.
Key responsibilities include:
- Continue to develop the Information Security Strategy, ensuring alignment to the Company’s IT strategy and business goals and create the required metric reporting to track progress to be presented to the Board.
- Communicate the information security strategy to relevant parties, as well as developing supporting policies and procedures required to meet the strategy.
- Develop, maintain, and expand the Cyber Risk Management Framework as part of the overall Information Security Management System (“ISMS”).
- Responsible for the Company’s information security capabilities, including the technical training and awareness of colleagues, ensuring it remains prepared against an ever-changing threat landscape.
- Work with the other department heads to develop a security community and security conscious culture.
- Contribute to design and architectural decisions and improve the approach to the Company’s threat modelling.
- Lead on information security incidents and work directly with internal teams and external parties on containment and mitigation activities, as well as preparing for incidents by running threat simulations, tabletop and red team exercises.
- Assess emerging and potential security threats using the Cyber Risk Management Framework and act proactively to mitigate relevant threats.
- End-to-end vulnerability management across the hybrid cloud environment.
- Manage security toolset, including managing the relationship with the third-party provided SOC.
- Provide security reviews of new technologies to support business strategy such as AI.
- Provide a standard assurance response to customers regarding our security posture.
- Support bid and tender responses by providing relevant information.
Preferred skills, qualifications and experience:
- Industry certifications such as CISSP, CCSP, CISM, or equivalent.
- Expert in information security.
- Strong understanding of cloud security principles and best practices, particularly in AWS.
- Experience in managing security incidents and leading incident response.
- Excellent knowledge of security frameworks, standards, and regulations, including ISO 27001, SOC 2, HIPAA, GDPR, etc.
- Good communication and interpersonal skills, with the ability to effectively communicate security-related questions to technical and non-technical stakeholders (employees, customers, and/or partners).
- Project management skills, with the ability to manage projects such as processes implementation and improvement, security systems implementation.
- Ability to collaborate cross-functionally and influence stakeholders at all levels of the organisation.
Heywood combines a passion for software with Agile methodologies to create modern software and data solutions and services for businesses, pension providers and third parties that help transform how their members and customers manage their lifelong financial journeys. Working for an expanding established market leader, you will have a real voice to influence our evolution. Continued learning and progression is ingrained in our daily life, encouraged through a variety of forums from e-learning subscriptions and a monthly down-tools day (“Hive Day”) and communities of practice for learning and experimentation. Our open culture encourages wide participation and innovation. We also reward our hard work through regular socials, organised by our people. Socials events include fiercely competitive bake-offs, Pride month office parties, sporting events, games nights and much more! We are committed to a hybrid working model, combining remote and office-based working.
As an equal opportunities’ employer, Heywood is committed to the equal treatment of all current and prospective employees and does not condone discrimination on the basis of age, disability, sex, sexual orientation, pregnancy and maternity, race or ethnicity, religion or belief, gender identity, or marriage and civil partnership. We aspire to have a diverse and inclusive workplace and strongly encourage suitably qualified applicants from a wide range of backgrounds to apply and join Heywood.
Contact Detail:
Heywood Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Head of Information Security
✨Tip Number 1
Familiarise yourself with the latest trends in information security, especially in hybrid cloud environments. Being able to discuss current threats and solutions during your interview will demonstrate your expertise and passion for the field.
✨Tip Number 2
Network with professionals in the information security sector, particularly those who have experience in cloud security. Engaging in discussions or attending relevant events can provide insights and connections that may help you stand out.
✨Tip Number 3
Prepare to showcase your hands-on experience with incident management and response. Be ready to share specific examples of how you've successfully handled security incidents in the past, as this will highlight your practical skills.
✨Tip Number 4
Understand the company's culture and values by researching their approach to security and innovation. Tailoring your conversation to align with their ethos during interviews can significantly enhance your chances of making a positive impression.
We think you need these skills to ace Head of Information Security
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights your experience in information security, particularly in hybrid cloud environments. Emphasise any relevant certifications like CISSP or CCSP, and showcase your hands-on experience with managing cybersecurity incidents.
Craft a Compelling Cover Letter: In your cover letter, express your passion for shaping information security strategies. Discuss how your skills align with the company's goals and mention specific examples of how you've successfully managed security vulnerabilities in the past.
Showcase Technical Expertise: When detailing your experience, focus on your technical security expertise. Highlight your understanding of cloud security principles, incident response management, and familiarity with security frameworks like ISO 27001 and GDPR.
Prepare for Potential Questions: Anticipate questions related to your approach to developing an information security strategy and managing security incidents. Be ready to discuss your experience with threat modelling and how you would contribute to a security-conscious culture within the company.
How to prepare for a job interview at Heywood
✨Showcase Your Strategic Vision
As the Head of Information Security, it's crucial to demonstrate your ability to develop and communicate a clear information security strategy. Be prepared to discuss how you would align this strategy with the company's IT goals and present metrics to track progress.
✨Highlight Your Technical Expertise
Make sure to emphasise your hands-on experience with cloud security principles, particularly in AWS. Discuss specific incidents you've managed and how your technical skills have helped mitigate risks in a hybrid cloud environment.
✨Demonstrate Incident Management Skills
Prepare to share examples of how you've led incident response efforts in the past. Highlight your experience with threat simulations and your approach to managing security incidents, as this will be key to the role.
✨Communicate Effectively with Stakeholders
Since the role requires collaboration across various departments, practice explaining complex security concepts in simple terms. Show that you can engage both technical and non-technical stakeholders effectively.